mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
5.8 KiB
5.8 KiB
| 1 | azureadrole | azuretemplateid | isprvilegedadrole | description |
|---|---|---|---|---|
| 2 | *Application Administrator* | *9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3* | TRUE | Can create and manage all aspects of app registrations and enterprise apps. |
| 3 | *Application Developer* | *cf1c38e5-3621-4004-a7cb-879624dced7c* | TRUE | Can create application registrations independent of the Users can register applications setting. |
| 4 | *Authentication Administrator* | *c4e39bd9-1100-46d3-8c65-fb160da0071f* | TRUE | Can access to view, set and reset authentication method information for any non-admin user. |
| 5 | *Authentication Extensibility Administrator* | *25a516ed-2fa0-40ea-a2d0-12923a21473a* | TRUE | Customize sign in and sign up experiences for users by creating and managing custom authentication extensions. |
| 6 | *Authentication Policy Administrator* | *526716b-113d-4c15-b2c8-68e3c22b9f80* | TRUE | Can create and manage the authentication methods policy, tenant-wide MFA settings, password protection policy, and verifiable credentials. |
| 7 | *Azure AD Joined Device Local Administrator* | *9f06204d-73c1-4d4c-880a-6edb90606fd8* | TRUE | Users assigned to this role are added to the local administrators group on Azure AD-joined devices. |
| 8 | *Azure DevOps Administrator* | *e3973bdf-4987-49ae-837a-ba8e231c7286* | TRUE | Can manage Azure DevOps policies and settings. |
| 9 | *Azure Information Protection Administrator* | *7495fdc4-34c4-4d15-a289-98788ce399fd* | TRUE | Can manage all aspects of the Azure Information Protection product. |
| 10 | *B2C IEF Keyset Administrator* | *aaf43236-0c0d-4d5f-883a-6955382ac081* | TRUE | Can manage secrets for federation and encryption in the Identity Experience Framework (IEF). |
| 11 | *Cloud Application Administrator* | *158c047a-c907-4556-b7ef-446551a6b5f7* | TRUE | Can create and manage all aspects of app registrations and enterprise apps except App Proxy. |
| 12 | *Cloud Device Administrator* | *7698a772-787b-4ac8-901f-60d6b08affd2* | TRUE | Limited access to manage devices in Azure AD. |
| 13 | *Compliance Administrator* | *17315797-102d-40b4-93e0-432062caca18* | TRUE | Can read and manage compliance configuration and reports in Azure AD and Microsoft 365. |
| 14 | *Conditional Access Administrator* | *b1be1c3e-b65d-4f19-8427-f6fa0d97feb9* | TRUE | Can manage Conditional Access capabilities. |
| 15 | *Directory Synchronization Accounts* | *d29b2b05-8046-44ba-8758-1e26182fcf32* | TRUE | Only used by Microsoft Entra Connect service. |
| 16 | *Directory Writers* | *9360feb5-f418-4baa-8175-e2a00bac4301* | TRUE | Can read and write basic directory information. For granting access to applications, not intended for users. |
| 17 | *Domain Name Administrator* | *8329153b-31d0-4727-b945-745eb3bc5f31* | TRUE | Can manage domain names in cloud and on-premises. |
| 18 | *Exchange Administrator* | *29232cdf-9323-42fd-ade2-1d097af3e4de* | TRUE | Can manage all aspects of the Exchange product. |
| 19 | *External Identity Provider Administrator* | *be2f45a1-457d-42af-a067-6ec1fa63bc45* | TRUE | Can configure identity providers for use in direct federation. |
| 20 | *Global Administrator* | *62e90394-69f5-4237-9190-012177145e10* | TRUE | Can manage all aspects of Microsoft Entra ID and Microsoft services that use Microsoft Entra identities. |
| 21 | *Global Reader* | *f2ef992c-3afb-46b9-b7cf-a126ee74c451* | TRUE | Can read everything that a Global Administrator can, but not update anything. |
| 22 | *Groups Administrator* | *fdd7a751-b60b-444a-984c-02652fe8fa1c* | TRUE | Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports. |
| 23 | *Helpdesk Administrator* | *729827e3-9c14-49f7-bb1b-9608f156bbb8* | TRUE | Can reset passwords for non-administrators and Helpdesk Administrators. |
| 24 | *Hybrid Identity Administrator* | *8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2* | TRUE | Can manage AD to Azure AD cloud provisioning, Azure AD Connect, Pass-through Authentication (PTA), Password hash synchronization (PHS), Seamless Single sign-on (Seamless SSO), and federation settings. |
| 25 | *Intune Administrator* | *3a2c62db-5318-420d-8d74-23affee5d9d5* | TRUE | Can manage all aspects of the Intune product. |
| 26 | *License Administrator* | *4d6ac14f-3453-41d0-bef9-a3e0c569773a* | TRUE | Can manage product licenses on users and groups. |
| 27 | *Network Administrator* | *d37c8bed-0711-4417-ba38-b4abe66ce4c2* | TRUE | Can manage network locations and review enterprise network design insights for Microsoft 365 Software as a Service applications. |
| 28 | *Partner Tier1 Support* | *4ba39ca4-527c-499a-b93d-d9b492c50246* | TRUE | Do not use - not intended for general use |
| 29 | *Partner Tier2 Support* | *e00e864a-17c5-4a4b-9c06-f5b95a8d5bd8* | TRUE | Do not use - not intended for general use |
| 30 | *Password Administrator* | *966707d0-3269-4727-9be2-8c3a10f19b9d* | TRUE | Can reset passwords for non-administrators and Password Administrators. |
| 31 | *Privileged Authentication Administrator* | *7be44c8a-adaf-4e2a-84d6-ab2649e08a13* | TRUE | Can access to view, set and reset authentication method information for any user (admin or non-admin) |
| 32 | *Privileged Role Administrator* | *e8611ab8-c189-46e8-94e1-60213ab1f814* | TRUE | Can manage role assignments in Azure AD, and all aspects of Privileged Identity Management. |
| 33 | *Security Administrator* | *194ae4cb-b126-40b2-bd5b-6091b380977d* | TRUE | Can read security information and reports, and manage configuration in Azure AD and Office 365. |
| 34 | *Security Operator* | *5f2222b1-57c3-48ba-8ad5-d4759f1fde6f* | TRUE | Creates and manages security events |
| 35 | *Security Reader* | *5d6b6bb7-de71-4623-b4af-96380a352509* | TRUE | Can read security information and reports in Microsoft Entra ID and Office 365. |
| 36 | *SharePoint Administrator* | *f28a1f50-f6e7-4571-818b-6a12f2af6b6c* | TRUE | Can manage all aspects of the SharePoint service. |
| 37 | *Teams Administrator* | *69091246-20e8-4a56-aa4d-066075b2a7a8* | TRUE | Can manage the Microsoft Teams service. |
| 38 | *User Administrator* | *fe930be7-5e62-47db-91af-98c3a49a38b1* | TRUE | Can manage all aspects of users and groups, including resetting passwords for limited admins. |
| 39 | *Windows 365 Administrator* | *11451d60-acb2-45eb-a7d6-43d0f0125c13* | TRUE | Can provision and manage all aspects of Cloud PCs. |